Question 631
Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?
Question 632
During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?
Question 633
Which of the following is MOST important to the effective management of an end user developed application?
Question 634
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?
Question 635
An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?
